S6E18 - Securing Access to Your Virtual Machines with Azure Bastion

S6E18 - Securing Access to Your Virtual Machines with Azure Bastion

In this episode, we explore Azure Bastion, Microsoft’s fully managed Platform-as-a-Service (PaaS) solution designed to provide secure Remote Desktop Protocol (RDP) and Secure Shell Protocol (SSH) access to Azure virtual machines (VMs). This Q&A-style episode dives deep into how Azure Bastion strengthens cloud security by eliminating the need for public IP addresses on VMs, reducing exposure to external threats like port scanning or protocol exploits. Alan poses critical questions about Azure Bastion’s functionality, architecture, deployment options, and integration with Azure’s security ecosystem, while our consultant delivers actionable insights tailored for IT administrators, security professionals, and cloud architects.

We cover:

  • Core Functionality: How Azure Bastion enables secure, clientless RDP/SSH access via the Azure portal or native clients, protecting VMs by removing public IP dependencies.
  • Architecture Breakdown: The role of the dedicated AzureBastionSubnet, private IP connectivity, and TLS-based sessions, including support for zonal deployments for high availability.
  • SKU Options: A detailed look at Developer, Basic, Standard, and Premium SKUs, highlighting features like session recording, Private Link integration, and host scaling for different organizational needs.
  • Security Integrations: How Azure Bastion works with Microsoft Defender for Cloud, Microsoft Entra ID (with MFA and conditional access), Azure Private Link, and Azure Monitor to enforce Zero Trust principles and ensure compliance.
  • Real-World Use Cases: Practical scenarios, such as secure admin access for global teams, compliance for regulated industries (e.g., healthcare, finance), and streamlined dev/test environments, with examples like Metinvest’s global VM management.
  • Best Practices: Tips for deployment (e.g., subnet sizing, VNet peering), security (e.g., MFA, NSG configuration), monitoring (e.g., Azure Monitor logs), and cost management (e.g., SKU selection, scaling strategies).
  • Limitations and Considerations: Key factors like SKU constraints, regional availability for zonal deployments, performance considerations, and cost implications, with guidance on mitigating challenges.

What did you think of this episode? Give us some feedback via our contact form, Or leave us a voice message in the bottom right corner of our site.

Read transcript

Episoder(155)

S5E30 - Azure Container Storage - Native container volume management in Azure

S5E30 - Azure Container Storage - Native container volume management in Azure

This week Alan and Sam discuss Azure Container Storage which is a volume management service built natively for containers, which enables cost-effective performance scaling and simplified management of...

23 Aug 202439min

S5E29 - External Attack Surface Management - Identify your digital assets.

S5E29 - External Attack Surface Management - Identify your digital assets.

Alan and Sam talk about External Attack Surface Management (EASM) and how Microsoft's Defender EASM helps discover and monitor your digital assets. Here are a few things we covered: What is External ...

16 Aug 202428min

S5E28 - Azure Storage Accounts - Scalable, secure cloud storage for data objects

S5E28 - Azure Storage Accounts - Scalable, secure cloud storage for data objects

This week Alan and Sam discuss Azure Storage Accounts which provide scalable, secure, and highly available cloud storage for various data types, including blobs, files, queues, and tables. It serves a...

9 Aug 202454min

S5E27 - Microsoft updates July - new products and features released

S5E27 - Microsoft updates July - new products and features released

This week, Alan and Sam talk about new features and services that have gone into Public Preview or General Available status in the last month. We dive into a couple of these updates that peaked our in...

2 Aug 202431min

S5E26 - Microsoft's Unified Security Operations Platform

S5E26 - Microsoft's Unified Security Operations Platform

Alan and Sam dive into Microsoft's Unified Security Operations Platform and how it can benefit SOC analysts in their day to day. Here are a few things we covered: What is a Security Operations Centre...

26 Jul 202442min

S5E25 - Azure Storage Actions - Serverless storage actions across your storage accounts

S5E25 - Azure Storage Actions - Serverless storage actions across your storage accounts

This week Alan and Sam discuss Azure Storage Actions a serverless framework currently in preview that allows users to perform common data operations on millions of objects across multiple Azure Storag...

19 Jul 202435min

S5E24 - Microsoft updates June - new products and features released

S5E24 - Microsoft updates June - new products and features released

This week, Alan and Sam talk about new features and services that have gone into Public Preview or General Available status in the last month. We dive into a couple of these updates that peaked our in...

12 Jul 202428min

S5E23 - Managed Identities for Azure Resources - Remove the need for secrets

S5E23 - Managed Identities for Azure Resources - Remove the need for secrets

Alan and Sam talk about the use of Managed Identities for Azure resources. Alan takes us through the methods used for programmatic access to Azure resources and the risks of some of the options. Here ...

28 Jun 202433min

Populært innen Teknologi

lydartikler-fra-aftenposten
romkapsel
teknisk-sett
energi-og-klima
nasjonal-sikkerhetsmyndighet-nsm
tomprat-med-gunnar-tjomlid
shifter
smart-forklart
rss-ki-praten
rss-impressions-2
elektropodden
hans-petter-og-co
pedagogisk-intelligens
rss-ai-forklart
fornybaren
rss-polypod
rss-alt-som-gar-pa-strom
rss-for-alarmen-gar
rss-bits-and-bytes-for-advokater
rss-startup